This Data Retention and Deletion Policy establishes the principles, procedures, and schedules governing how OwnerClone collects, retains, and deletes data obtained through our platform, including data received via third-party integrations such as Plaid. This Policy applies to all consumer data, restaurant operator data, and financial data processed by OwnerClone.
1. Purpose
This Policy fulfills requirements under our agreements with third-party data providers including Plaid and applies to all systems, personnel, and data assets operated by OwnerClone, Inc.
2. Scope
This Policy applies to:
- All personal and financial data collected from consumers and restaurant operators through the OwnerClone platform
- Data received from third-party data providers including Plaid, Stripe, and payment processors
- Bank account information, transaction data, and financial records processed through our bookkeeping and financial management modules
- Employee and labor data processed through our scheduling and payroll modules
- All data stored in our Supabase-hosted database infrastructure
3. Data Categories and Retention Periods
3.1 Consumer Financial Data (Plaid)
- Bank account connection tokens: Retained only for the duration of the active connection. Revoked immediately upon disconnection.
- Transaction data pulled from Plaid: Retained for 7 years to support accounting, bookkeeping, and tax compliance requirements.
- Account balance and institution data: Retained for the duration of the active restaurant account plus 1 year.
3.2 Restaurant Operator Account Data
- Account credentials and profile information: Retained for the duration of the active account plus 90 days following account termination.
- Sales and POS data: Retained for 7 years to support financial reporting and tax compliance.
- Payroll and labor records: Retained for 7 years in accordance with FLSA requirements.
- Food cost, inventory, and operational data: Retained for 3 years.
3.3 Employee Data
- Time clock, scheduling, and payroll data: Retained for 7 years following the last date of employment at the restaurant.
- Employee profile information: Deleted within 90 days of account deactivation unless required for payroll compliance.
3.4 System and Application Logs
- Application logs: Retained for 90 days then automatically purged.
- Security and access logs: Retained for 1 year.
- Error logs: Retained for 30 days.
3.5 Agent and Chat Data
- AI agent conversation logs: Retained for 1 year to support agent memory and service continuity.
- Agent memory summaries: Retained for the duration of the active account.
4. Legal Basis for Retention
Data is retained on the following legal bases:
- Contract performance: Data necessary to deliver our platform services to restaurant operators and their employees.
- Legal obligation: Financial, payroll, and tax records retained to comply with IRS, FLSA, and applicable state regulations.
- Legitimate interest: Operational and security logs retained to maintain platform integrity and investigate incidents.
- Consent: Marketing and preference data retained only while consent remains active.
5. Data Deletion Procedures
5.1 Account Termination
When a restaurant operator terminates their OwnerClone account:
- Active account data is flagged for deletion within 30 days of termination request.
- Financial and payroll records subject to legal retention requirements are retained for the applicable statutory period then deleted.
- Plaid connection tokens are revoked immediately upon account termination.
- Backups containing account data are purged within 90 days of the scheduled deletion date.
5.2 Consumer Deletion Requests
Consumers and restaurant employees may request deletion of their personal data by contacting [email protected]. Upon receipt of a verified deletion request:
- We will confirm receipt within 5 business days.
- We will complete deletion of non-legally-required data within 30 days.
- We will notify the requestor of completion or explain any data that must be retained due to legal obligations.
5.3 Plaid Data Deletion
- Access tokens are revoked immediately when a consumer disconnects their bank account.
- Transaction and balance data is retained for the period specified in Section 3.1 unless a deletion request is received.
- Upon receiving a verified deletion request, Plaid-sourced data not subject to legal retention requirements will be deleted within 30 days.
6. Data Security During Retention
During the retention period, all data is protected by:
- Encryption at rest via AES-256 encryption at the infrastructure level through our Supabase-hosted database.
- Encryption in transit via TLS 1.2 or higher on all data transmissions enforced by our Vercel deployment infrastructure.
- Access controls limiting database access to authorized personnel only.
- Row-level security policies enforced at the database layer to prevent cross-tenant data access.
7. Third-Party Data Processors
OwnerClone works with the following third-party processors that may retain data subject to their own retention policies:
- Supabase: Database hosting and infrastructure. Data is hosted in US-East AWS regions.
- Vercel: Application hosting and content delivery.
- Plaid: Bank account connectivity. Governed by Plaid's privacy policy.
- Stripe: Payment processing. Governed by Stripe's privacy policy.
- Anthropic: AI processing for agent functionality. Processed per Anthropic's API data retention policy.
8. Policy Review and Updates
This Policy is reviewed annually or whenever significant changes occur to our data processing activities, applicable law, or third-party provider relationships. Updates will be posted at this URL with an updated effective date. Material changes will be communicated to active restaurant operators via email.
9. Contact